🪟 Windows TippsThe Gemini desktop app is now available for Windows(11.09.2026 um 17:06 Uhr)
🪟 Windows TippsAnnouncing new builds for 11 September 2026(11.09.2026 um 19:11 Uhr)
🪟 Windows TippsChild account not showing in Microsoft Family(11.09.2026 um 11:11 Uhr)
🪟 Windows TippsUnable to connect to localhost MySQL workbench(11.09.2026 um 14:07 Uhr)
⚠️ Malware / Trojaner / VirenWindows 11 just dropped the tool ransomware abused, Microsoft says don’t restore WMIC(10.09.2026 um 20:11 Uhr)
🪟 Windows TippsThe Gemini desktop app is now available for Windows(11.09.2026 um 17:06 Uhr)
🪟 Windows TippsAnnouncing new builds for 11 September 2026(11.09.2026 um 19:11 Uhr)
🪟 Windows TippsChild account not showing in Microsoft Family(11.09.2026 um 11:11 Uhr)
🪟 Windows TippsUnable to connect to localhost MySQL workbench(11.09.2026 um 14:07 Uhr)
⚠️ Malware / Trojaner / VirenWindows 11 just dropped the tool ransomware abused, Microsoft says don’t restore WMIC(10.09.2026 um 20:11 Uhr)

🕵️ Sicherheitslücken 🕛 vor 4 Tagen 1 Min Lesezeit CVE-2024-11114
0

DEFCONConference: DEF CON SG1 - CSIT Village - Ernest Ang - From Chrome Renderer, To Mouse To System

Cyber Threat & Vulnerability Dossier CVSS 7.5 HIGH (Heuristik) EPSS 93.5%
ANGRIPPSVEKTOR
💻 Lokal
AUTHENTIFIZIERUNG
🔓 Keine Authentifizierung nötig
SCHADENSPROFIL
RCE / Vollzugriff / Full Compromise
CWE-KLASSIFIZIERUNG
CWE-94: Code Injection
Handlungsempfehlung: Patch-Tuesday Update einspielen oder betroffene Dienste in Windows Defender isolieren.
Im CVE-Radar öffnen
↗ Quelle (YouTube · DEFCONConference)
🗣️ Stimme:
📺
YouTube · DEFCONConference
8.1k YouTube-Aufrufe
You click on a link. A download prompt appears. Your mouse suddenly seems to take on a life of its own and clicks the pop-up. Before you know it, your Windows machine belongs to me.

This session breaks down an amusing and far-fetched (yet entirely technical) exploit chain, starting from the highly restrictive Chromium renderer process and escalating to kernel-level privileges by chaining and abusing three vulnerabilities: CVE-2024-5274, CVE-2024-11114, and CVE-2025-29824. I will be sharing my learnings, laughs and grief while venturing into V8, Mojo, CLFS and everything in between (i.e. Ubercage, kCFG) while attempting to make this work.
Vollständiger Original-Bericht
Ausführliche Details, Code-Beispiele & Hersteller-Stellungnahme auf youtube.com.
↗ Original-Artikel auf youtube.com lesen
Wie bewertest du diesen Beitrag?
1 Klick Feedback
Teilen mit Netzwerk & Team:

Community-Analysen & Experten-Meinungen 0

Verfasse deine eigene Analyse, teile Workarounds oder diskutiere diesen Vorfall im Blog.
Noch keine Community-Analyse verfasst. Markiere einen Textabschnitt oder klicke oben auf Eigene Analyse verfassen“!
Community Pulse: Relevanz-Einschätzung
1 Klick Experten-Votum
🔴 Akute Relevanz 0%
🟡 In Evaluierung 0%
🟢 Keine Auswirkung 0%
Spannende Innovation 0%
Verwandte Story-Cluster & Quellen (Vektor-KI)
Port 8095 Engine
1 Quelle
Birmingham, Ala., Resident Sues Over Data Center Tax Abatements
1 Quelle
'Maybe that is how Transformers started': Readers react to the possibility of AI becoming self-aware
1 Quelle
Anthropic spent this week in hot water over cybersecurity